VulnerAlert



GOOGLE
MICROSOFT
ORACLE
02-07-2025 19:27

CVE-2025-34091 Vulnerabilidad documentada

8.8 HIGH
Tags
#google
#windows
#form
#db
#chrome
#add
#oracle
#microsoft
#vulnerability
#browser
#affected
#privilege
#issue
#errors
#error
#allow
#attack
#affect
Descripción
A padding oracle vulnerability exists in Google Chrome’s AppBound cookie encryption mechanism due to observable decryption failure behavior Windows Event Logs when handling malformed ciphertext SYSTEM-DPAPI-encrypted blobs. A local attacker can repeatedly send ciphertexts the Chrome elevation service and distinguish between MAC errors, enabling a attack. This allows partial of SYSTEM-DPAPI layer eventual recovery user-DPAPI encrypted key, which is trivially decrypted by attacker’s own context. issue undermines core purpose Encryption low-privileged theft through cryptographic misuse verbose error feedback. Confirmed with enabled. Other Chromium-based browsers may be affected if they implement similar COM-based mechanisms. This arises from combination implementation way Microsoft DPAPI reports failures via Logs. As such, relies on visibility all supported versions Windows.
https://vulncheck.com/advisories/google-chrome-appbound-cookie-encryption
https://www.cyberark.com/resources/threat-research-blog/c4-bomb-blowing-up-chromes-appbound-cookie-encryption
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2025-34091
Resultados similares
Coincidentes en almenos en 50% de los tags
15-07-2025
Linux : Oracle Linux 7 ELSA-2025-9741 important: perl-File-Find-Rule security issue The followi...
Ver información
10-07-2025 CVE-2025-38324
In the Linux kernel, the following vulnerability has been resolved: mpls: Use rcu_dereference_...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por